Skip to scanner
READ-ONLY CODE REVIEW

Check what matters before you ship.

Security checks for AI-built apps. Paste a public GitHub repository to see supported risks, the source evidence behind them, and what Pallos could not verify.

Use a repository you own or are authorized to review. Public repositories only.
No accountNo GitHub connectionRead-only
REAL FINDING · OWASP JUICE SHOP

A user-derived value reaches eval.

A stored username flows into executable code in this intentionally insecure training app. Pallos marks the source-level pattern high confidence; it does not claim a deployed exploit.

SUPPORTED CHECKS

What Pallos reviews.

Only supported source patterns are evaluated. Missing evidence is marked unverified, never passed.

Secrets
Authorization
Database access
API routes
Client/server boundaries
Dependencies
Project configuration
See all checks and limits
REVIEW A CHANGE

What did this PR introduce?

Compare supported changed files at the base and head commits. See new source patterns, persistent findings, and what Pallos could not verify. No account required.

Review a public PR
READ-ONLY · NO ACCOUNT FOR PUBLIC REPOS

Check your next commit.

Pallos does not edit, push, or deploy code.

NOT TESTED

Checks Pallos could not verify

A passed result means no supported pattern was found in the reviewed source. Untested means Pallos lacked the source, configuration, or runtime evidence required to evaluate it.